CVE-2024-38553Improper Locking in Linux

Severity
5.5MEDIUMNVD
OSV8.8OSV6.5OSV4.7
EPSS
0.0%
top 98.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 19
Latest updateApr 3

Description

In the Linux kernel, the following vulnerability has been resolved: net: fec: remove .ndo_poll_controller to avoid deadlocks There is a deadlock issue found in sungem driver, please refer to the commit ac0a230f719b ("eth: sungem: remove .ndo_poll_controller to avoid deadlocks"). The root cause of the issue is that netpoll is in atomic context and disable_irq() is called by .ndo_poll_controller interface of sungem driver, however, disable_irq() might sleep. After analyzing the implementation of

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages9 packages

NVDlinux/linux_kernel3.26.6.33+2
Debianlinux/linux_kernel< 6.1.119-1+2
Ubuntulinux/linux_kernel< 5.4.0-204.224+4
CVEListV5linux/linux7f5c6addcdc039c1a7c435857e6284ecac5d97c8e2348d8c61d03feece1de4c05f72e6e99f74c650+5
debiandebian/linux< linux 6.1.119-1 (bookworm)

Patches

🔴Vulnerability Details

25
OSV
linux-iot vulnerabilities2025-04-03
OSV
linux-kvm vulnerabilities2025-02-24
OSV
linux, linux-aws, linux-lts-xenial vulnerabilities2025-02-10
OSV
linux-azure vulnerabilities2025-02-03
OSV
linux-azure, linux-azure-4.15 vulnerabilities2025-01-30

📋Vendor Advisories

24
Ubuntu
Linux kernel (IoT) vulnerabilities2025-04-03
Ubuntu
Linux kernel (KVM) vulnerabilities2025-02-24
Ubuntu
Linux kernel vulnerabilities2025-02-10
Ubuntu
Linux kernel (Azure) vulnerabilities2025-02-03
Ubuntu
Linux kernel (Azure) vulnerabilities2025-01-30